JPH10285153A - Communication system, ic card issue registration system, key code generator and recording medium - Google Patents
Communication system, ic card issue registration system, key code generator and recording mediumInfo
- Publication number
- JPH10285153A JPH10285153A JP9081708A JP8170897A JPH10285153A JP H10285153 A JPH10285153 A JP H10285153A JP 9081708 A JP9081708 A JP 9081708A JP 8170897 A JP8170897 A JP 8170897A JP H10285153 A JPH10285153 A JP H10285153A
- Authority
- JP
- Japan
- Prior art keywords
- card
- communication
- key
- code
- key file
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Granted
Links
- 238000004891 communication Methods 0.000 title claims abstract description 151
- 238000000034 method Methods 0.000 claims description 28
- 230000007246 mechanism Effects 0.000 claims description 27
- 230000004044 response Effects 0.000 claims description 13
- 230000005540 biological transmission Effects 0.000 claims description 5
- 238000012800 visualization Methods 0.000 claims description 4
- 230000008569 process Effects 0.000 claims description 3
- 238000004590 computer program Methods 0.000 claims description 2
- 238000012545 processing Methods 0.000 description 14
- 238000010586 diagram Methods 0.000 description 10
- 230000006870 function Effects 0.000 description 10
- 238000005516 engineering process Methods 0.000 description 7
- 238000003780 insertion Methods 0.000 description 6
- 230000037431 insertion Effects 0.000 description 6
- 238000001514 detection method Methods 0.000 description 2
- 238000010295 mobile communication Methods 0.000 description 2
- 125000002066 L-histidyl group Chemical group [H]N1C([H])=NC(C([H])([H])[C@](C(=O)[*])([H])N([H])[H])=C1[H] 0.000 description 1
- 235000017858 Laurus nobilis Nutrition 0.000 description 1
- 244000125380 Terminalia tomentosa Species 0.000 description 1
- 235000005212 Terminalia tomentosa Nutrition 0.000 description 1
- 230000004913 activation Effects 0.000 description 1
- 230000002457 bidirectional effect Effects 0.000 description 1
- 238000010276 construction Methods 0.000 description 1
- 238000011161 development Methods 0.000 description 1
- 230000000694 effects Effects 0.000 description 1
- 238000005538 encapsulation Methods 0.000 description 1
- 238000002438 flame photometric detection Methods 0.000 description 1
- 230000006872 improvement Effects 0.000 description 1
- 238000012544 monitoring process Methods 0.000 description 1
Abstract
Description
【0001】[0001]
【発明の属する技術分野】本発明は、例えば通信技術を
併用したエレクトリックコマースや企業の営業情報のよ
うな情報の機密保持技術に係り、特に、公衆網に接続さ
れた通信相手装置との間に仮想専用回線を構築する通信
機構の起動時に用いるキーファイルの機密性を高める技
術に関する。BACKGROUND OF THE INVENTION 1. Field of the Invention The present invention relates to a technology for keeping information confidential, such as electric commerce or business information of a company using a communication technology, and more particularly to a technology for communicating with a communication partner device connected to a public network. The present invention relates to a technique for increasing the confidentiality of a key file used when starting a communication mechanism for constructing a virtual private line.
【0002】[0002]
【従来の技術】公衆網を用いたデータ通信において、第
三者によるデータ傍受やデータ改竄が容易に起こり得る
ことは周知のとおりである。そのため、例えばエレクト
リックコマースの分野で使用される電子現金のように、
機密性の高いデータを通信媒体を用いて伝送しあう場
合、公衆網は不適であり、別途、専用回線を敷設する必
要があった。しかし、専用回線を用いたデータ通信で
は、通信コストを低減させることができないばかりでな
く、個々の通信端末間、ないしネットワーク間を直接結
ぶ通信形態、つまり、1対1の通信形態しか実現でき
ず、1対n(nは自然数、以下同じ)、あるいはn対n
の通信形態をとることができない。そのため、例えば企
業において、本社と複数の支社との間の相互連絡、ある
いは本社又は支社と携帯型移動端末を所持する複数の社
員との間の連絡設定を行うサービスを専用回線を実現す
ることは困難であった。2. Description of the Related Art It is well known that data interception and data tampering by a third party can easily occur in data communication using a public network. Therefore, for example, electronic cash used in the field of electric commerce,
When transmitting highly confidential data using a communication medium, the public network is unsuitable, and a separate dedicated line has to be laid. However, in data communication using a dedicated line, not only the communication cost cannot be reduced, but also a communication mode in which individual communication terminals or networks are directly connected, that is, only a one-to-one communication mode can be realized. , 1: n (n is a natural number, the same applies hereinafter), or n: n
Communication form cannot be taken. Therefore, for example, in a company, it is not possible to implement a dedicated line for a service for performing a mutual communication between the head office and a plurality of branch offices or a communication setting between a head office or a branch office and a plurality of employees having a portable mobile terminal. It was difficult.
【0003】そこで、最近は、データ暗号技術、認証技
術、対象データを隠蔽するカプセル化技術等を応用し
て、公衆網上に仮想的に閉じたネットワーク回線ないし
個別回線(以下、仮想専用回線)を構築し、この仮想専
用回線を用いてデータ通信を行う試みもなされている。[0003] Therefore, recently, by applying data encryption technology, authentication technology, encapsulation technology for concealing target data, or the like, a network line or individual line virtually closed on a public network (hereinafter, a virtual private line). Attempts have also been made to construct data communication using this virtual private line.
【0004】図14は、公衆網に仮想専用回線を構築し
てデータ通信を行う通信システムの一例を示す概念図で
ある。この通信システムは、例えば、通信サーバ80
と、固定型通信端末81と、リモート環境で使用される
一または複数の移動型通信端末84、85とを含んで構
成される。FIG. 14 is a conceptual diagram showing an example of a communication system for establishing a virtual private line in a public network and performing data communication. This communication system is, for example, a communication server 80
And a fixed communication terminal 81 and one or a plurality of mobile communication terminals 84 and 85 used in a remote environment.
【0005】通信サーバ80及び固定型通信端末81に
は、それぞれ公衆網LPに接続された通信相手との間に
仮想専用回線VTを構築するためのVPN(仮想専用回
線ネットワーク)サーバ82、あるいはVPN装置83
が接続される。また、移動型通信端末84,85は、そ
れぞれソフトウエアによって自端末と通信相手装置との
間に上記仮想専用回線VTを構築するためのVPN構築
部841,851を有している。なお、VPNサーバ8
2,VPN装置83、VPN構築部841,851は、
それぞれ基本的な機能は、実質的に同一となるものであ
る。The communication server 80 and the fixed communication terminal 81 are provided with a VPN (virtual leased line network) server 82 or a VPN for establishing a virtual leased line VT with a communication partner connected to the public network LP, respectively. Device 83
Is connected. Each of the mobile communication terminals 84 and 85 has a VPN constructing unit 841 or 851 for constructing the virtual private line VT between its own terminal and a communication partner device by software. Note that the VPN server 8
2, the VPN device 83 and the VPN construction units 841 and 851
The basic functions are substantially the same.
【0006】この通信システムにおいて、例えば固定型
通信端末81から通信サーバ80に対象データを伝送す
る場合、VPN装置83が、まず、通信端末81からパ
ケット(端末アドレスを含む)を受信し、これVPNサ
ーバ82の公開鍵を用いて暗号化するとともに、この暗
号化されたパケットにヘッダを付加する。ヘッダには、
自己のアドレスと通信相手であるVPN装置83のアド
レスとが含まれる。VPN装置83は、また、ヘッダを
もとに経路制御を行い、このパケットを通信サーバ80
側に送る。なお、公衆網LPがインターネットの場合、
ヘッダ(IPヘッダ)に基づく経路制御は、所定ポイン
トに設置されたルータが行う。In this communication system, for example, when transmitting target data from the fixed communication terminal 81 to the communication server 80, the VPN device 83 first receives a packet (including a terminal address) from the communication terminal 81, and then receives the packet. The encryption is performed using the public key of the server 82, and a header is added to the encrypted packet. The header contains
It contains its own address and the address of the VPN device 83 that is the communication partner. The VPN device 83 also performs route control based on the header, and transmits this packet to the communication server 80.
Send to the side. When the public network LP is the Internet,
Route control based on the header (IP header) is performed by a router installed at a predetermined point.
【0007】VPNサーバ82は、受信したパケットか
らヘッダを取り除いた後、自己の秘密鍵を用いてパケッ
トの復号化を行い、これにより再生された対象データを
通信サーバ80に送る。これにより、通信コストの低い
公衆網LPを用いながら、第三者からのデータ傍受等を
排除し得る機密性の高いデータの相互通信が可能にな
る。上記通信システムによれば、1対n、ないしn対n
の通信形態の実現が容易となり、機密情報をオンライン
で通信相手に伝達する種々の情報伝達システムの構築が
可能になる。[0007] After removing the header from the received packet, the VPN server 82 decrypts the packet using its own secret key, and sends the target data reproduced thereby to the communication server 80. As a result, it is possible to perform highly confidential data mutual communication that can eliminate data interception or the like from a third party while using the public network LP having a low communication cost. According to the above communication system, 1: n or n: n
This facilitates the realization of this communication mode, and makes it possible to construct various information transmission systems for transmitting confidential information to a communication partner online.
【0008】例えば、企業固有の営業情報をその企業の
社員に周知するための企業情報管理機構を通信サーバ8
0に接続しておき、各通信端末81,84,85を操作
する社員が、仮想専用回線VTと通信サーバ80とを介
して上記企業情報管理機構にアクセスする形態の情報伝
達システムを考える。この場合、企業側の営業情報管理
者は、パスワードや暗号化及び復号化に用いる鍵等の社
員の個人情報を格納したキーファイルを社員毎に発行
し、これをICカードのようなセキュリティ性の高い機
密性記録媒体に格納して複数の社員に配布する。各社員
は、自己が操作する通信端末のメモリ領域に、上記IC
カードを通じて配布されたキーファイルを格納してお
き、操作時に当該通信端末において認証処理がなされる
ようにする。すなわち、通信端末から操作者に対してパ
スワード入力を促し、予めキーファイルに設定してある
パスワードと入力されたパスワードとを比較することに
よって、操作者が正規の社員であることを通信端末が識
別できるようにする。正規の社員であると判定された場
合、該当する通信端末は、通信サーバ80との間に呼を
確立し、上記営業情報を取得できるようにする。このよ
うにして、セキュリティ性の高い機密情報の1対nの情
報伝達を可能にしている。[0008] For example, a company information management mechanism for disseminating business information unique to a company to employees of the company is provided by the communication server 8.
0, and an employee who operates each of the communication terminals 81, 84, 85 accesses the enterprise information management mechanism via the virtual private line VT and the communication server 80. In this case, the business information manager of the company issues a key file storing employee's personal information such as a password and a key used for encryption and decryption for each employee, and transmits the key file to a security device such as an IC card. Store it on a highly confidential recording medium and distribute it to multiple employees. Each employee stores the above IC in the memory area of the communication terminal operated by himself / herself.
A key file distributed through a card is stored, and authentication processing is performed in the communication terminal during operation. In other words, the communication terminal prompts the operator to enter a password, and compares the password set in the key file with the entered password, so that the communication terminal can identify that the operator is a regular employee. It can be so. If it is determined that the employee is a regular employee, the corresponding communication terminal establishes a call with the communication server 80 so that the sales information can be obtained. In this manner, one-to-n information transmission of confidential information with high security is enabled.
【0009】[0009]
【発明が解決しようとする課題】ところで、例えば上述
のような情報伝達システムでは、社員毎のキーファイル
の作成権限は、本来、営業情報管理者のみとすべきであ
る。しかし、実際には、周知のように、通信サーバ80
のシステム管理者(スーパバイザ)としての権限を有す
る者であれば、上記キーファイルの作成は可能である。
そのため、悪意の第三者によってシステム管理者の識別
情報(ID)やパスワードが盗用された場合は、不正な
キーファイルの新規発行や、登録済情報の削除、改竄が
可能になってしまう。By the way, in the information transmission system as described above, for example, the authority to create a key file for each employee should be originally limited to only the sales information manager. However, in practice, as is well known, the communication server 80
Anyone who has authority as a system administrator (supervisor) can create the key file.
Therefore, if the identification information (ID) or password of the system administrator is stolen by a malicious third party, it becomes possible to newly issue an unauthorized key file, delete or falsify registered information.
【0010】また、キーファイルの配布時に、悪意の第
三者によってそのキーファイルが窃盗された場合は、パ
スワードが容易に探し出され、不正行為がなされる危険
性があった。そのため、仮想専用回線を構築し得る通信
システムを用いた場合であっても、機密情報の送受を行
う上で限界があり、改善が望まれていた。If the key file is stolen by a malicious third party at the time of distribution of the key file, there is a risk that the password is easily searched out and an illegal act is performed. Therefore, even when a communication system capable of constructing a virtual private line is used, there is a limit in transmitting and receiving confidential information, and improvement has been desired.
【0011】そこで本発明は、通信時におけるキーファ
イルの第三者への漏洩を防止することができる通信関連
技術を提供することを課題とする。本発明の他の課題
は、仮想専用回線の利用時に用いられるキーファイルの
作成権限のセキュリティ性をより高め、悪意の第三者に
キーファイルが漏洩されにくくする、キーファイルの作
成・配布に関する改良技術を提供することにある。Accordingly, an object of the present invention is to provide a communication-related technique capable of preventing a key file from leaking to a third party during communication. Another object of the present invention is to improve the security of the authority to create a key file used when using a virtual leased line and make it difficult for a malicious third party to leak the key file. To provide technology.
【0012】[0012]
【課題を解決するための手段】上記課題を解決するた
め、本発明は、公衆網に接続された通信相手装置との間
に仮想専用回線を構築する通信機構と、少なくとも前記
通信機構の利用権限情報及び利用者の識別情報を含むキ
ーファイルが機密的に格納されたICカードと、このI
Cカードを離脱自在に装着する機構及び動作時に参照さ
れるメモリを備えた通信装置と、を有する通信システム
を提供する。この通信システムにおいて、前記通信装置
は、前記ICカードの装着を契機に当該ICカードに格
納されているキーファイルを復号して前記記憶手段に展
開し、該展開されたキーファイルに基づき前記通信機構
を起動して前記通信相手装置との間に仮想専用回線を構
築するともに、前記通信機構の動作終了後は、当該キー
ファイルを前記記憶手段から削除するように構成され
る。また、前記通信機構の動作中に前記ICカードが離
脱されたことを検知したときは、当該通信機構の動作を
停止させるとともに、前記キーファイルを前記記憶手段
から削除するように構成される。SUMMARY OF THE INVENTION In order to solve the above-mentioned problems, the present invention provides a communication mechanism for establishing a virtual private line with a communication partner device connected to a public network, and at least authority to use the communication mechanism. An IC card in which a key file containing information and user identification information is confidentially stored;
Provided is a communication system having a mechanism for detachably mounting a C card and a communication device having a memory referred to during operation. In this communication system, the communication device decrypts the key file stored in the IC card upon loading of the IC card and expands the key file in the storage unit, and based on the expanded key file, the communication mechanism. To establish a virtual private line with the communication partner device, and delete the key file from the storage unit after the operation of the communication mechanism ends. Further, when it is detected that the IC card is removed during the operation of the communication mechanism, the operation of the communication mechanism is stopped and the key file is deleted from the storage means.
【0013】好ましい形態として、前記通信装置に、前
記キーファイルの内容の可視化を規制する可視化規制手
段を設ける。また、前記ICカードに、格納されている
キーファイルに基づいて利用者認証を行う認証手段と、
前記認証手段による誤認回数が一定回数に達したときは
当該キーファイルをロックするロック手段とを設ける。As a preferred mode, the communication device is provided with a visualization restricting means for restricting visualization of the contents of the key file. An authentication unit for performing user authentication based on a key file stored in the IC card;
Lock means for locking the key file when the number of misrecognitions by the authentication means reaches a certain number is provided.
【0014】また、上記他の課題を解決するため、本発
明は、上記通信システムにおいて使用される前記ICカ
ードを発行するICカード発行登録システムを提供す
る。このICカード発行登録システムは、前記ICカー
ドの発行を統括する発行統括者固有の統括者暗号コード
及び前記ICカードの発行を担当する発行担当者固有の
担当者暗号コードを機密保持するカード発行装置と、前
記キーファイルを作成して登録するキー管理装置とを双
方向通信可能に接続して成り、前記キー管理装置は、所
定権限に基づいて取得した統括者暗号コードを登録する
手段と、登録済の統括者暗号コードに基づきチャレンジ
・レスポンス方式によって発行担当者登録要求の認証を
行い、認証結果が正当のときに、前記統括者暗号コード
で暗号化された前記担当者暗号コードを前記カード発行
装置より取得する手段と、取得した担当者暗号コードを
登録済の統括者暗号コードで復号化して登録する手段
と、を備え、登録済の担当者暗号コードに基づく認証後
に前記キーファイルの作成を行うように構成されている
ことを特徴とする。According to another aspect of the present invention, there is provided an IC card issuance / registration system for issuing the IC card used in the communication system. This IC card issuance / registration system is a card issuance apparatus that keeps secret information of an administrator's encryption code unique to an issuance manager who supervises the issuance of the IC card and a person's encryption code unique to an issuer in charge of issuing the IC card. And a key management device for creating and registering the key file, which are connected in a bidirectional manner so that the key management device can register the supervisory code acquired based on a predetermined authority. The issuer registration request is authenticated by the challenge-response method based on the already-executed supervisor encryption code, and when the authentication result is valid, the supervisor encryption code encrypted with the supervisor encryption code is issued to the card. Means for acquiring from the device, and means for decrypting and registering the acquired person's encryption code with the registered supervisor's encryption code. Characterized in that it is configured after authentication based on user cryptographic code to perform creation of the key file.
【0015】本発明は、また、上記通信システムにおい
て使用される前記ICカードを発行するシステムであっ
て、少なくとも前記ICカードの発行を担当する発行担
当者固有の担当者暗号コードを機密保持するカード発行
装置と、前記キーファイルを作成して登録するキー管理
装置とを双方向通信可能に接続して成り、前記キー管理
装置は、所定権限に基づいて取得した前記担当者暗号コ
ードを登録する手段と、登録済の担当者暗号コードに基
づきチャレンジ・レスポンス方式によってキーファイル
作成要求の認証を行い、認証結果が正当のときに渡した
所定の機密性セッションキーを用いて、前記カード発行
装置からのファイル基礎情報の取得、及びこのファイル
基礎情報に基づいて作成した前記キーファイルのカード
発行装置への送信を行う手段と、を備え、前記カード発
行装置は、前記作成されたキーファイルを対象ICカー
ドに機密的に格納するように構成されていることを特徴
とするICカード発行登録システムをも提供する。[0015] The present invention also relates to a system for issuing the IC card used in the communication system, wherein at least the secret code of a person in charge of issuing the IC card is kept secret. An issuing device and a key management device for creating and registering the key file are connected so as to be capable of two-way communication, and the key management device registers the person-in-charge code acquired based on predetermined authority. And a key file creation request is authenticated by a challenge-response method based on the registered person's encryption code, and a predetermined confidentiality session key passed when the authentication result is valid is sent from the card issuing device. Acquisition of file basic information and transmission of the key file created based on the file basic information to a card issuing device And means for performing, wherein the card issuing apparatus also provides an IC card issuing registration system characterized by being configured to store confidential to a subject IC card the created key file.
【0016】前記担当者暗号コードは、例えば、前記カ
ード発行装置に装着された発行担当者専用のICカード
に機密的に格納されており、当該ICカードが装着され
ている間だけ上記処理ができるようにする。また、発行
担当者固有のキーファイルについては、前記発行担当者
専用のICカードに機密的に格納されるようにしてもよ
い。The person in charge code is confidentially stored, for example, in an IC card dedicated to the person in charge attached to the card issuing device, and the above processing can be performed only while the IC card is attached. To do. The key file unique to the issuer may be confidentially stored in the IC card dedicated to the issuer.
【0017】本発明は、また、上記ICカード発行登録
システムにおいて使用されるキーコード生成装置をも提
供する。この装置は、少なくとも前記統括者暗号コード
及び担当者暗号コードの作成基礎となる基礎情報を格納
した記憶手段と、前記セッションキーの基礎となる乱数
を生成する乱数発生手段と、前記記憶手段に格納された
基礎情報及び前記乱数発生手段から出力される乱数を所
定の権限情報に基づいて暗号化する暗号化手段と、を有
し、前記権限情報の入力を契機に前記統括者暗号コー
ド、担当者暗号コード、及びセッションキーのいずれか
を生成するように構成されているものである。この装置
において、前記記憶手段を揮発性メモリで構成し、不正
読み出しないし通電の遮断によって前記基礎情報が消滅
するように構成することが機密性を高める上で効果的と
なる。The present invention also provides a key code generation device used in the IC card issuance / registration system. This device includes a storage unit that stores at least basic information that is a basis for creating the supervisor encryption code and the person-in-charge code, a random number generation unit that generates a random number that is a basis for the session key, and a storage unit that stores the random number. Encryption means for encrypting the generated basic information and the random number output from the random number generation means based on predetermined authority information, wherein the input of the authority information triggers the manager encryption code, It is configured to generate either an encryption code or a session key. In this device, it is effective to increase the confidentiality if the storage means is constituted by a volatile memory and the basic information is erased by unauthorized reading or interruption of power supply.
【0018】本発明は、さらに、公衆網に接続された通
信相手装置との間に仮想専用回線を構築する通信機構を
利用するための利用権限情報及び利用者の識別情報を含
むキーファイルが機密的に格納されたICカードを離脱
自在に装着する機構と、記憶手段とを備えたコンピュー
タ装置に、前記ICカードが装着されて所定の認証処理
が終了したときに、当該ICカードに格納されているキ
ーファイルを前記記憶手段に展開させ、該展開されたキ
ーファイルに基づき前記通信機構を起動させて前記通信
相手装置との間に仮想専用回線を構築させ、さらに、前
記ICカードの離脱時または前記通信機構の動作終了時
に当該キーファイルを前記メモリから削除させるための
コンピュータプログラムを、前記コンピュータ装置が読
み取り可能な形態で記録して成る記録媒体を提供する。According to the present invention, a key file including use right information and user identification information for using a communication mechanism for establishing a virtual private line with a communication partner device connected to a public network is confidential. When a predetermined authentication process is completed after the IC card is mounted on a computer device having a mechanism for detachably mounting the IC card that is stored in a removable manner and a storage unit, the IC card is stored in the IC card. The key file is expanded in the storage means, and the communication mechanism is activated based on the expanded key file to establish a virtual private line with the communication partner device. A form in which the computer device can read a computer program for deleting the key file from the memory when the operation of the communication mechanism ends. Providing a recording medium comprising recording.
【0019】[0019]
【発明の実施の形態】以下、図面を参照して本発明の実
施の形態を詳細に説明する。図1は、本発明のICカー
ド発行登録システムの要部構成図である。このICカー
ド発行登録システム1は、公衆網上に仮想専用回線を構
築する通信機構の利用権限情報及び利用者の識別情報を
含むキーファイルを格納したICカード30を発行する
もので、コンピュータ装置により実現されるキー管理装
置10及びカード発行装置20と、キーコード発生装置
(SCD)40,41とを備えて構成される。この実施
形態で用いるICカード30は、内部に、PIN(個人
識別情報:パスワードとして使用される場合もある)格
納部と、このPINによる認証を行う認証処理手段とを
有するものである。キーコード発生装置(SCD)4
0,41は、同一機能のものであるが、後述するよう
に、出力されるキーコードが異なるものである。Embodiments of the present invention will be described below in detail with reference to the drawings. FIG. 1 is a configuration diagram of a main part of an IC card issuance / registration system of the present invention. This IC card issuance / registration system 1 issues an IC card 30 storing a key file including use authority information of a communication mechanism for establishing a virtual private line on a public network and identification information of a user. It comprises a key management device 10 and a card issuing device 20 to be realized, and key code generation devices (SCDs) 40 and 41. The IC card 30 used in this embodiment has a PIN (personal identification information: sometimes used as a password) storage unit and an authentication processing unit for performing authentication using the PIN. Key code generator (SCD) 4
Numerals 0 and 41 have the same function, but output different key codes as described later.
【0020】キー管理装置10は、カード発行装置20
との間の通信制御を行う通信制御部11と、チャレンジ
・レスポンス方式によって認証を行う認証処理部12
と、カード発行装置20への送信情報を暗号化するとと
もにカード発行装置20からの受信情報を復号化する暗
号処理部13と、仮想専用回線を構築する際に使用され
るキーファイルを作成するキーファイル作成部14と、
発行統括者、発行担当者、及び、利用者IDやパスワー
ド等のキー情報等を登録するID登録部15を備えて構
成される。図中、ITTは発行端末管理表、IPTは発
行担当者管理表、TKTは仮想専用回線用キー管理表で
ある。The key management device 10 includes a card issuing device 20
A communication control unit 11 for performing communication control between the server and an authentication processing unit 12 for performing authentication by a challenge-response method
And an encryption processing unit 13 for encrypting information transmitted to the card issuing device 20 and decrypting information received from the card issuing device 20, and a key for creating a key file used when constructing a virtual private line A file creation unit 14,
It comprises an issuance supervisor, an issuance person in charge, and an ID registration unit 15 for registering key information such as a user ID and a password. In the figure, ITT is an issue terminal management table, IPT is an issuer management table, and TKT is a virtual private line key management table.
【0021】一方、カード発行装置20は、キー管理装
置10との間の通信制御を行う通信制御部21と、操作
者の認証を行う認証処理部22と、キー管理装置10へ
の送信情報を暗号化するとともにキー管理装置10から
の受信情報を復号化する暗号処理部23と、ICカード
30からの情報読み込み及びICカード30への情報書
き込みの際のインタフェースとなるカード入出力インタ
フェース部24と、ICカード30を離脱自在に装着す
るカードリーダライタ25と、ICカード30の挿抜を
検出する着脱検出部26と、キーボード等から成るデー
タ入力装置27を備えて構成される。On the other hand, the card issuing apparatus 20 includes a communication control section 21 for controlling communication with the key management apparatus 10, an authentication processing section 22 for authenticating an operator, and transmitting information transmitted to the key management apparatus 10. An encryption processing unit 23 for encrypting and decrypting information received from the key management device 10; a card input / output interface unit 24 serving as an interface for reading information from the IC card 30 and writing information to the IC card 30; , A card reader / writer 25 for removably mounting the IC card 30, a detachable detector 26 for detecting insertion and removal of the IC card 30, and a data input device 27 including a keyboard and the like.
【0022】図2は、例えばキー管理装置10に接続さ
れて使用されるキーコード発生装置(SCD)の外観図
である。このキーコード発生装置40は、高機密性が要
求されるキーコード、例えば統括者暗号コード等を生成
したり、後述するチャレンジコードやセッションキーを
生成するもので、RS−232C等のインタフェースを
介してキー管理装置10に接続されるようになってい
る。このキーコード発生装置40では、ハードウエア及
びソフトウエアの両面から使用のセキュリティ性を確保
している。ハードウエアによるセキュリティは、物理鍵
A,B(42a,42b)をそれぞれ該当する鍵挿入孔
41a,41bに差し込むことで実現される。一方、ソ
フトウエアによるセキュリティは、パスワード等による
論理鍵による認証処理により実現される。キーコード発
生装置40は、また、平文情報を暗号化するために利用
されるマスターキー、ID、パスワード等を用いて種々
のキーコードを生成する制御手段を有している。FIG. 2 is an external view of a key code generator (SCD) used by being connected to the key management device 10, for example. The key code generation device 40 generates a key code requiring high confidentiality, for example, a supervisor encryption code or the like, or generates a challenge code or a session key to be described later, via an interface such as RS-232C. Connected to the key management device 10. In the key code generator 40, the security of use is ensured from both hardware and software. Hardware security is realized by inserting the physical keys A and B (42a, 42b) into the corresponding key insertion holes 41a, 41b, respectively. On the other hand, software security is realized by authentication processing using a logical key such as a password. The key code generation device 40 also has control means for generating various key codes using a master key, an ID, a password, and the like used for encrypting plaintext information.
【0023】図3は、上記制御手段の機能ブロック構成
図である。この制御手段は、図示しないCPU(マイク
ロプロセッサ)が所定のプログラムを読み込んで実行す
ることにより、キー管理装置10との間の情報の入出力
のインタフェースとなるI/Oインタフェース部51
と、物理鍵の挿入を検知して起動の可否を決定する起動
制御部52と、各種キーコードを作成するための基礎情
報となるマスターキー541,統括者用パスワード54
2,担当者用ID及びパスワード、その他、利用者に関
するキー情報等の格納領域を有するメモリ54と、この
メモリ54への情報書込及びメモリ54からの情報読み
出しを制御するメモリ制御部53と、認証処理部55
と、乱数発生部56と、暗号化処理部57と、キーコー
ド生成部58とを備えて構成される。FIG. 3 is a functional block diagram of the control means. The control means includes an I / O interface unit 51 serving as an information input / output interface with the key management device 10 when a CPU (microprocessor) (not shown) reads and executes a predetermined program.
A start control unit 52 that detects insertion of a physical key and determines whether or not to start, a master key 541 serving as basic information for creating various key codes, and a supervisor password 54
2, a memory 54 having a storage area for a person-in-charge ID and password, and other key information related to the user; a memory control unit 53 for controlling writing of information to the memory 54 and reading of information from the memory 54; Authentication processing unit 55
, A random number generator 56, an encryption processor 57, and a key code generator 58.
【0024】メモリ54は揮発性のメモリであり、この
キーコード発生装置40が接続されるコンピュータ装置
側から使用中止が指示された場合、あるいはこの装置が
強制的に分解された場合に、これがメモリ制御部53に
通知され、メモリ54内の情報が消去されるようになっ
ている。The memory 54 is a volatile memory. When the computer device to which the key code generator 40 is connected instructs to stop using the device, or when the device is forcibly disassembled, the memory 54 is used as a memory. The control unit 53 is notified and the information in the memory 54 is deleted.
【0025】認証処理部55は、キー管理装置10等か
らの入力パスワードや物理鍵42a,42bの挿入状態
(権限情報)によって各種キーコード生成可否の認証を
行うものである。暗号化処理部57は、メモリ54に記
録されているマスターキーと所定の暗号アルゴリズムと
を用いて、乱数発生部56で生成した乱数や統括者用パ
スワード、発行担当者用ID及びパスワード等の暗号化
を行うものである。この場合の暗号アルゴリズムとして
は、例えばSXALというブロック単位の暗号アルゴリ
ズムとMBALというマルチブロック単位の暗号アルゴ
リズムとを組み合わせた「SXAL/MBAL」(IS
O/IEC9979−0012)を用いることができ
る。キーコード生成部58は、暗号化処理部57を用い
て要求に応じたキーコードを生成し、I/Oインタフェ
ース部51を通じてキー管理装置10等に送出する。な
お、カード発行装置20に接続されるキーコード発生装
置41も同様の構成となる。The authentication processing section 55 authenticates the generation of various key codes based on the input password from the key management device 10 and the insertion states (authority information) of the physical keys 42a and 42b. The encryption processing unit 57 uses the master key recorded in the memory 54 and a predetermined encryption algorithm to encrypt the random number generated by the random number generation unit 56, the password for the supervisor, the ID for the issuer, and the password. It is to make. As the encryption algorithm in this case, for example, “SXAL / MBAL” (IS) in which a block-based encryption algorithm called SXAL and a multi-block encryption algorithm called MBAL are combined.
O / IEC9979-0012) can be used. The key code generation unit 58 generates a key code according to the request using the encryption processing unit 57 and sends the key code to the key management device 10 and the like via the I / O interface unit 51. The key code generator 41 connected to the card issuing device 20 has the same configuration.
【0026】次に、ICカード発行登録システム1の動
作を具体的に説明する。本実施形態では、発行統括者登
録フェーズ、発行担当者登録フェーズ、及びICカード
発行フェーズをこの順に実行する。また、ICカード3
0が発行された場合は、利用者操作フェーズ(通信シス
テムの運用モード)に移行する。以下、各フェーズにつ
いて説明する。Next, the operation of the IC card issuance / registration system 1 will be specifically described. In the present embodiment, the issuing supervisor registration phase, the issuing person registration phase, and the IC card issuing phase are executed in this order. IC card 3
If 0 is issued, the process proceeds to the user operation phase (operation mode of the communication system). Hereinafter, each phase will be described.
【0027】(1)発行統括者登録フェーズ まず、発行統括者の登録手順を、図4のシーケンスチャ
ートを参照して説明する。キー管理装置10に発行端末
管理表ITTを作成し、発行統括者がログインする際に
使用する統括者ID、例えば「TORIGAI」を直接登録す
る(k11,k12)。次に、カード発行装置20から
統括者ID「TORIGAI」でログインする(c11)。キ
ー管理装置10は、この統括者IDがITTに登録され
ている統括者IDと比較し、一致する場合は、良好通知
をカード発行装置20に送る(k13)。カード発行装
置20は、統括者暗号コード(暗号化乱数:X,X,・・・X)
を生成し、これをキー管理装置10に転送する(c1
2)。なお、統括者暗号コードは、キーコード発生装置
41に物理鍵Bを挿入し、且つ統括者者用キーワード等
を入力することにより取得する。キー管理装置10は、
この統括者暗号コードを自装置の暗号鍵で暗号化して
(X',X',・・・X')、発行端末管理表ITTに記録する。
このときの発行端末管理表ITTの記録内容例を図5に
示す。(1) Issuance Supervisor Registration Phase First, the registration procedure of the issuance supervisor will be described with reference to the sequence chart of FIG. The issuing terminal management table ITT is created in the key management device 10, and the supervisor ID used when the issuing supervisor logs in, for example, “TORIGAI” is directly registered (k11, k12). Next, the user logs in from the card issuing device 20 with the supervisor ID “TORIGAI” (c11). The key management device 10 compares this supervisor ID with the supervisor ID registered in the ITT, and sends a good notification to the card issuing device 20 if they match (k13). The card issuance device 20 has a manager encryption code (encrypted random numbers: X, X,... X).
Is generated and transferred to the key management device 10 (c1
2). The supervisor encryption code is obtained by inserting the physical key B into the key code generator 41 and inputting a supervisor key or the like. The key management device 10
This supervisor encryption code is encrypted with its own encryption key (X ′, X ′,... X ′) and recorded in the issuing terminal management table ITT.
FIG. 5 shows an example of the recorded contents of the issuing terminal management table ITT at this time.
【0028】(2)発行担当者登録フェーズ 次に、発行担当者の登録手順を図6のシーケンスチャー
トを参照して説明する。発行担当者の登録は、発行統括
者が行う。すなわち、カード発行装置20に発行担当
者、例えば「FUJII」の識別IDをもつ発行担者用IC
カードを装着し(c21)、発行統括者が統括者ID
「TORIGAI」でログインする(c22)。キー管理装置
10は、カード発行装置20から送られた統括者IDと
発行端末管理表ITT上に記録されている統括者IDと
を比較し(k21)、一致したときは、乱数から成るチ
ャレンジコードを生成し、これをカード発行装置20に
送る(k22)。また、このチャレンジコードを発行端
末管理表ITT上の統括者暗号コードで暗号化し(k2
3)、これを参照レスポンスとして保持しておく。カー
ド発行装置20は、チャレンジコードを統括者暗号コー
ドで暗号化し、これをレスポンスコードとしてキー管理
装置10に送る(c23)。キー管理装置10は、レス
ポンスコードと参照レスポンスとの突き合わせを行い、
一致したときは、発行担当者登録の許可を発行端末に通
知する(k24)。カード発行装置20は、発行担当者
用ICカードから発行担当者の識別IDやIC認証コー
ド等を読み出し(c24)、これらを暗号化してキー管
理装置10へ転送する(c25)。キー管理装置10
は、IC認証コード等を発行端末管理表ITTに記録さ
れた統括者暗号コードで復号化し(k25)、発行担当
者管理表IPTに記録する(k26)。但し、IC認証
コードについては、キー管理装置10で管理している暗
号鍵で再び暗号化し、これを担当者暗号コードとしてI
PTに記録する。このようにして記録された発行担当者
管理表IPTの内容例を図7に示す。(2) Issuer Registration Phase Next, the procedure for registering the issuer will be described with reference to the sequence chart of FIG. Registration of the person in charge of issuance is performed by the issuance supervisor. In other words, the card issuing device 20 has an issuer, for example, an issuer IC having an identification ID of “FUJII”.
The card is attached (c21), and the issuing supervisor has the supervisor ID.
Login with “TORIGAI” (c22). The key management device 10 compares the supervisor ID sent from the card issuing device 20 with the supervisor ID recorded on the issuing terminal management table ITT (k21), and when they match, a challenge code composed of a random number. Is generated and sent to the card issuing device 20 (k22). Also, this challenge code is encrypted with the supervisor code on the issuing terminal management table ITT (k2
3), this is stored as a reference response. The card issuing device 20 encrypts the challenge code with the supervisor encryption code, and sends this to the key management device 10 as a response code (c23). The key management device 10 compares the response code with the reference response,
If they match, the issuing terminal is notified of the permission of the issuer registration (k24). The card issuing device 20 reads the ID of the issuing person, the IC authentication code, and the like from the issuing person's IC card (c24), encrypts these, and transfers it to the key management device 10 (c25). Key management device 10
Decrypts the IC authentication code and the like with the supervisor encryption code recorded in the issuing terminal management table ITT (k25), and records it in the issuing person management table IPT (k26). However, the IC authentication code is re-encrypted with the encryption key managed by the key management device 10, and this is used as the person-in-charge encryption code.
Record on PT. FIG. 7 shows an example of the contents of the issuer management table IPT thus recorded.
【0029】(3)利用者用ICカードの発行フェーズ 利用者用のICカードの発行は、登録された発行担当者
が行う。図8及び図9は、この場合の登録手順を示すシ
ーケンスチャートである。図8において、発行担当者用
ICカードを装着し、正しいパスワードによる認証がな
されると(c31)、カード発行装置20は、自動的に
発行担当者の識別IDをキー管理装置10に送る(c3
1)。つまり、発行担当者自身がICカード30の内容
を意識することなく、キー管理装置10との間の通信が
確立される。キー管理装置10は、カード発行装置20
から送られた識別IDと発行担当者管理表IPT上の識
別IDとを比較し(k31)、一致したときは、キーコ
ード生成装置40を用いてチャレンジコード(乱数1)
を生成し、これをカード発行装置20に送信する(k3
2)。また、このチャレンジコードを発行担当者管理表
IPT上のIC認証コードで暗号化し(k33)、これ
を参照レスポンスとして保持しておく。カード発行装置
20は、チャレンジコードをIC認証コード(担当者暗
号コード)で暗号化し、レスポンスコードとしてキー管
理装置10に送る(c32)。キー管理装置10は、レ
スポンスコードと参照レスポンスとの突き合わせを行い
(k34)、一致したときは、キーファイル生成を許可
する旨を通知する。キー管理装置10は、また、SCD
40で生成したセッションキー(乱数2)を暗号化して
カード発行装置20に送信する(k35)。(3) Issuance phase of user's IC card The issuance of a user's IC card is performed by a registered issuer. 8 and 9 are sequence charts showing the registration procedure in this case. In FIG. 8, when the issuer IC card is inserted and authentication with a correct password is performed (c31), the card issuing device 20 automatically sends the ID of the issuer to the key management device 10 (c3).
1). In other words, communication with the key management device 10 is established without the issuer himself being aware of the contents of the IC card 30. The key management device 10 includes a card issuing device 20
Is compared with the identification ID on the issuer management table IPT (k31), and when they match, the challenge code (random number 1) is obtained using the key code generation device 40.
Is generated and transmitted to the card issuing device 20 (k3
2). Further, this challenge code is encrypted with an IC authentication code on the issuer management table IPT (k33), and this is stored as a reference response. The card issuing device 20 encrypts the challenge code with an IC authentication code (person-in-charge code) and sends it to the key management device 10 as a response code (c32). The key management device 10 compares the response code with the reference response (k34), and when they match, notifies that the key file generation is permitted. The key management device 10 also includes an SCD
The session key (random number 2) generated in 40 is encrypted and transmitted to the card issuing device 20 (k35).
【0030】図9に移り、カード発行装置20は、暗号
化されたセッションキーを、発行担当者用ICカードの
IC認証コードで復号化するとともに(c33)、キー
ファイル生成に必要なファイル基礎情報(利用者ID、
キー情報)をセッションキーで暗号化してキー管理装置
10に転送する(c34)。キー管理装置10は、カー
ド発行装置20から送られた情報をセッションキーで復
号化し(k36)、キーファイルを作成し、これを仮想
専用回線用キー管理表TKTへ記録する(k37)。ま
た、作成したキーファイルをセッションキーで暗号化し
てカード発行装置20へ転送する(k38)。カード発
行装置20は、暗号化されたキーファイルをセッション
キーで復号化し(c35)、これをICカード30へ機
密的に格納する(c36)。このようにして作成された
仮想専用回線用キー管理表TKTの内容例を図10に示
す。Referring to FIG. 9, the card issuing device 20 decrypts the encrypted session key with the IC authentication code of the IC card for the issuing person (c33), and also provides file basic information necessary for key file generation. (User ID,
The key information) is encrypted with the session key and transferred to the key management device 10 (c34). The key management device 10 decrypts the information sent from the card issuing device 20 with the session key (k36), creates a key file, and records this in the virtual private line key management table TKT (k37). The created key file is encrypted with the session key and transferred to the card issuing device 20 (k38). The card issuing device 20 decrypts the encrypted key file with the session key (c35), and stores this in the IC card 30 confidentially (c36). FIG. 10 shows an example of the contents of the virtual private line key management table TKT thus created.
【0031】(4)利用者操作 次に、上述のようにして作成されたICカード30を用
いた通信システムについて説明する。この実施形態で
は、図11に示すように、公知のファイアオール(F
W)61,上述のキー管理装置10を含んで成るVPN
サーバ62,DBサーバ63、上述のカード発行装置2
0をローカルネットワークLL1で接続し、公衆網LP
及びローカルネットワークLL2に接続された通信端末
2a,2bとの間で仮想専用回線VTを介して会員間通
信を行う通信システム2の例を挙げる。(4) User Operation Next, a communication system using the IC card 30 created as described above will be described. In this embodiment, as shown in FIG. 11, a known fireall (F
W) 61, VPN comprising the key management device 10 described above
Server 62, DB server 63, card issuing device 2 described above
0 via a local network LL1 and a public network LP
An example of the communication system 2 for performing inter-member communication via the virtual leased line VT between the communication terminals 2a and 2b connected to the local network LL2 will be described.
【0032】VPNサーバ62は公衆網LPに仮想専用
回線(VT)を構築する通信機構であり、ファイアオー
ル61は、周知のように会員外の通信装置から自ネット
への侵入を防止するものである。DBサーバ63は、会
員に提供するための情報を蓄積したものであり、本例で
は、通信端末2aのターゲットサーバとなるものであ
る。通信端末2a,2bは会員用の通信装置であり、両
者は同一機能のものなので、以下、一つの通信端末2a
についてのみ説明する。The VPN server 62 is a communication mechanism for constructing a virtual private line (VT) in the public network LP, and the fireall 61 is for preventing intrusion from a non-member communication device into its own network as is well known. is there. The DB server 63 stores information to be provided to members, and in this example, serves as a target server for the communication terminal 2a. The communication terminals 2a and 2b are member communication devices and have the same function.
Will be described only.
【0033】通信端末2aは、図12の要部構成図に示
すように、仮想専用回線VTとの間の通信制御を行う通
信制御部71と、アプリケーション部(AP)72と、
ディスク等のメモリ73と、このメモリ73への情報書
込やメモリ73からの情報読み出しを制御するメモリ制
御部74と、ICカード30を離脱自在に装着するカー
ドリーダライタ75と、ICカード30に格納された情
報を展開するカード情報展開部76と、ICカードの挿
抜を検出する着脱検出部77とを備えて構成される。I
Cカード30は、上述のICカード発行登録システム1
によりキーファイルが機密的に格納されたものである
が、ICカードの基本機能であるPIN(個人識別情
報)によるパスワード認証機能と、この認証の結果、不
正入力が所定回数継続した場合はロックする機能とを併
有するものである。As shown in FIG. 12, the communication terminal 2a includes a communication control unit 71 for controlling communication with the virtual private line VT, an application unit (AP) 72,
A memory 73 such as a disk, a memory control unit 74 for controlling writing of information to the memory 73 and reading of information from the memory 73, a card reader / writer 75 for detachably mounting the IC card 30; It comprises a card information expanding section 76 for expanding the stored information, and a detachment detecting section 77 for detecting insertion and removal of an IC card. I
The C card 30 is the IC card issuance / registration system 1 described above.
Although the key file is stored confidentially, a password authentication function using a PIN (personal identification information), which is a basic function of the IC card, is locked if unauthorized input continues a predetermined number of times as a result of this authentication. It has both functions.
【0034】なお、通信端末2aにおける上記各機能ブ
ロック71〜74,76〜77は、例えばパーソナルコ
ンピュータのようなコンピュータ装置と所定のプログラ
ムとの協働によって実現される。このプログラムは、通
常、コンピュータ装置と一体に組み込まれるが、コンピ
ュータ装置とは分離した形態でコンピュータ読み取り可
能な記録媒体、例えばCD−ROMやフレキシブルディ
スクに記録され、適宜コンピュータ装置に適宜インスト
ールされて使用されるものであってもよい。The above functional blocks 71 to 74 and 76 to 77 in the communication terminal 2a are realized by cooperation of a computer such as a personal computer and a predetermined program. This program is usually integrated with the computer device, but is recorded on a computer-readable recording medium, for example, a CD-ROM or a flexible disk in a form separated from the computer device, and is appropriately installed in the computer device and used. May be performed.
【0035】AP72は、相手側の通信装置70との間
で行う通信内容を規定するとともに、この通信内容を公
開鍵方式と共通鍵方式のハイブリッド方式により暗号化
ないし復号化を行う機能を有する。また、メモリ制御部
74を介して取得したメモリ73内の記録情報、特にキ
ーファイルについてはその表示を規制する機能、着脱検
出部78の状態を監視してICカード30が抜かれた場
合に通信を中断する機能をも有する。つまり、ICカー
ド30が装着されている場合のみ通信を可能にする。The AP 72 has a function of defining communication contents to be performed with the communication apparatus 70 of the other party and encrypting or decrypting the communication contents by a hybrid method of a public key method and a common key method. In addition, a function of restricting the display of the record information in the memory 73 obtained through the memory control unit 74, particularly the key file, a function of monitoring the state of the attachment / detachment detection unit 78 and performing communication when the IC card 30 is removed. It also has a function to interrupt. That is, communication is enabled only when the IC card 30 is mounted.
【0036】この通信端末2aを用いた通信手順は、図
13に示すとおりである。すなわち、通信端末2aを操
作する利用者が自己のICカード30をカードリーダラ
イタ75に装着すると、通信端末2aは、着脱検出部7
8でICカード装着を検出し(ステップS101:Ye
s)、パスワードによる利用者認証がなされると(ステ
ップS102:Yes)、メモリ制御部74を通じて当該
ICカード30に格納されているキーファイルをメモリ
73へ展開する(ステップS103)。その後、通信制
御部71を通じて利用者IDをVPNサーバ62内のキ
ー管理装置10へ送信する。なお、パスワードの不正入
力が6回続いた場合、そのICカード30はロックさ
れ、使用不能となる。The communication procedure using this communication terminal 2a is as shown in FIG. That is, when the user operating the communication terminal 2a inserts his / her own IC card 30 into the card reader / writer 75, the communication terminal 2a
In step S101, the IC card is detected (step S101: Ye).
s) When the user authentication with the password is performed (Step S102: Yes), the key file stored in the IC card 30 is developed in the memory 73 through the memory control unit 74 (Step S103). Thereafter, the user ID is transmitted to the key management device 10 in the VPN server 62 through the communication control unit 71. If the password is incorrectly entered six times, the IC card 30 is locked and cannot be used.
【0037】VPNサーバ62内のキー管理装置10で
は、通信端末2aから送られた利用者IDがキー管理装
置10の仮想専用回線管理表TKTに記録されているか
どうかをチェックし、記録されている場合は、そのキー
情報を用いて会員サービスによる認証チェックを行う。
認証が正当の場合はアクセス許可を当該通信端末2aに
通知する(ステップS104)。The key management device 10 in the VPN server 62 checks whether the user ID sent from the communication terminal 2a is recorded in the virtual private line management table TKT of the key management device 10 and records it. In this case, an authentication check by the member service is performed using the key information.
If the authentication is valid, the access permission is notified to the communication terminal 2a (step S104).
【0038】これにより、通信端末2aのAP72は、
図11の破線で示す仮想専用回線VTを通じてターゲッ
トとなるDBサーバ63との間に呼を確立し、公開鍵方
式と共通鍵方式のハイブリッド方式による暗号化通信を
開始する(ステップS105)。通信端末2aは、通信
中にICカード30が抜かれたことを検知した場合(ス
テップS106:No,ステップS107:Yes)、あ
るいは通信が終了した場合(ステップS106:Yes)
は、キーファイルをメモリ73から削除する(ステップ
S108)。このようにして、通信時におけるセキュリ
ティ性を確保しつつ、仮想専用回線VTを用いた通信が
可能なる。Thus, the AP 72 of the communication terminal 2a
A call is established with the target DB server 63 via the virtual leased line VT indicated by the broken line in FIG. 11, and encrypted communication using a hybrid method of the public key method and the common key method is started (step S105). The communication terminal 2a detects that the IC card 30 has been removed during the communication (Step S106: No, Step S107: Yes) or ends the communication (Step S106: Yes).
Deletes the key file from the memory 73 (step S108). In this manner, communication using the virtual private line VT can be performed while ensuring security during communication.
【0039】[0039]
【発明の効果】以上の説明から明らかなように、本発明
のICカード発行登録システムによれば、発行統括者の
みが発行担当者を規定することができ、また、発行担当
者のみがキーファイルを機密的に格納した利用者用のI
Cカードを発行することができるので、キーファイルの
作成権限のセキュリティ性が高まり、悪意の第三者にキ
ーファイルが漏洩されにくくなるという特有の効果があ
る。しかも、キーファイルは、ICカード固有の情報に
より暗号化して格納されているため、別のICカードへ
複製してキーファイルを正しく復元することは不可能と
なる。As is clear from the above description, according to the IC card issuance / registration system of the present invention, only the issuing supervisor can specify the issuing person, and only the issuing person can enter the key file. I for users who have secretly stored
Since the C card can be issued, the security of the authority to create the key file is enhanced, and the key file is less likely to be leaked to a malicious third party. In addition, since the key file is stored by being encrypted with information unique to the IC card, it is impossible to copy the key file to another IC card and restore the key file correctly.
【0040】また、本発明の通信システムによれば、キ
ーファイルが格納されたICカードが装着されていると
きのみ仮想専用回線を用いた通信が可能になり、且つI
Cカードが抜かれたときや、通信終了時にはキーファイ
ルが削除されるので、通信時のキーファイルのセキュリ
ティ性が高まる効果がある。また、通信開始時の認証の
際に、不正パスワードの入力が所定回数に達したときは
ICカードがロックするので、第三者がパスワード等の
内容を知得することは不可能であり、この点からもセキ
ュリティ性を高めることができる。According to the communication system of the present invention, communication using the virtual private line is enabled only when an IC card storing a key file is mounted.
Since the key file is deleted when the C card is removed or at the end of communication, there is an effect that the security of the key file at the time of communication is enhanced. Also, at the time of authentication at the start of communication, the IC card is locked when an unauthorized password is entered a predetermined number of times, so that it is impossible for a third party to know the contents of the password and the like. Therefore, security can be improved.
【図1】本発明のICカード発行登録システムの要部構
成図。FIG. 1 is a configuration diagram of a main part of an IC card issuance / registration system of the present invention.
【図2】本実施形態で用いるキーコード発生装置(SC
D)の外観図。FIG. 2 shows a key code generator (SC) used in the present embodiment.
D) Exterior view.
【図3】本実施形態のキーコード発生装置(SCD)の
機能ブロック構成図。FIG. 3 is a functional block configuration diagram of a key code generator (SCD) of the embodiment.
【図4】発行統括者の登録手順を示すシーケンスチャー
ト。FIG. 4 is a sequence chart showing a registration procedure of an issuing supervisor.
【図5】図4の手順によって形成される発行端末管理表
の内容説明図。FIG. 5 is an explanatory view of the contents of an issuing terminal management table formed by the procedure of FIG. 4;
【図6】発行担当者の登録手順を示すシーケンスチャー
ト。FIG. 6 is a sequence chart showing a procedure for registering a person in charge of issuance;
【図7】図6の手順によって形成される発行担当者管理
表の内容説明図。FIG. 7 is an explanatory view of the contents of an issuer management table formed by the procedure of FIG. 6;
【図8】利用者端末の登録手順を示すフローチャート。FIG. 8 is a flowchart showing a registration procedure of a user terminal.
【図9】利用者端末の登録手順を示すフローチャート
(続き)FIG. 9 is a flowchart showing a user terminal registration procedure (continued).
【図10】図8及び図9の手順によって形成される利用
者端末管理表の内容説明図。FIG. 10 is an explanatory diagram of the contents of a user terminal management table formed by the procedures of FIGS. 8 and 9;
【図11】本発明を適用した通信システムの構成図。FIG. 11 is a configuration diagram of a communication system to which the present invention is applied.
【図12】図11の通信システムを構成する通信端末の
ブロック構成図。FIG. 12 is a block configuration diagram of a communication terminal included in the communication system of FIG. 11;
【図13】図11の通信システム2における通信手順の
説明図。FIG. 13 is an explanatory diagram of a communication procedure in the communication system 2 of FIG. 11;
【図14】従来の通信システムの概略構成図。FIG. 14 is a schematic configuration diagram of a conventional communication system.
1 ICカード発行登録システム 2 通信システム 2a,2b 通信端末 10 キー管理装置 12,22,55 認証処理部 13,23,57 暗号処理部 14 キーファイル作成部 15 ID登録部 20 カード発行装置 24 カード入出力インタフェース部 25,75 カードリーダライタ 26,77 着脱検出部 30 ICカード 40,41 キーコード発生装置 52 起動制御部 53,74 メモリ制御部 54,73 メモリ 57 キーコード生成部 62 VPNサーバ 63 DBサーバ 72 アプリケーション部(AP) 76 カード情報展開部 LL1,LL2 ローカルネットワーク LP 公衆網 VT 仮想専用回線 DESCRIPTION OF SYMBOLS 1 IC card issue registration system 2 Communication system 2a, 2b Communication terminal 10 Key management device 12, 22, 55 Authentication processing unit 13, 23, 57 Encryption processing unit 14 Key file creation unit 15 ID registration unit 20 Card issuing device 24 Card insertion Output interface unit 25, 75 Card reader / writer 26, 77 Removal / attachment detection unit 30 IC card 40, 41 Key code generator 52 Activation control unit 53, 74 Memory control unit 54, 73 Memory 57 Key code generation unit 62 VPN server 63 DB server 72 Application part (AP) 76 Card information development part LL1, LL2 Local network LP Public network VT Virtual private line
───────────────────────────────────────────────────── フロントページの続き (72)発明者 藤井 幹雄 神奈川県横浜市青葉区あざみ野1丁目14番 地5 株式会社ローレルインテリジェント システムズ内 (72)発明者 中原 精一 東京都東大和市奈良橋三丁目488番地の3 (72)発明者 大沢 篤 東京都保谷市中町六丁目1番地29号 ────────────────────────────────────────────────── ─── Continued on the front page (72) Inventor Mikio Fujii 1-14-14 Azamino, Aoba-ku, Yokohama-shi, Kanagawa Prefecture 5 Inside Laurel Intelligent Systems Co., Ltd. (72) Inventor Seiichi Nakahara 3-488, Narabashi, Higashiyamato-shi, Tokyo Address No. 3 (72) Inventor Atsushi Osawa 1-29, Nakamachi 6-chome, Hoya-shi, Tokyo
Claims (11)
に仮想専用回線を構築する通信機構と、少なくとも前記
通信機構の利用権限情報及び利用者の識別情報を含むキ
ーファイルが機密的に格納されたICカードと、このI
Cカードを離脱自在に装着する機構及び動作時に参照さ
れる記憶手段を備えた通信装置と、を有し、前記通信装
置は、 前記ICカードの装着を契機に、当該ICカードに格納
されているキーファイルを復号して前記記憶手段に展開
し、該展開されたキーファイルに基づき前記通信機構を
起動して前記通信相手装置との間に仮想専用回線を構築
するともに、前記通信機構の動作終了後は、当該キーフ
ァイルを前記記憶手段から削除するように構成されてい
ることを特徴とする通信システム。1. A communication mechanism for establishing a virtual private line with a communication partner device connected to a public network, and a key file including at least usage authority information and user identification information of the communication mechanism is confidentially protected. The stored IC card and this I
A communication device having a mechanism for detachably mounting the C card and storage means referred to at the time of operation. The communication device is stored in the IC card when the IC card is mounted. The key file is decrypted and developed in the storage means, the communication mechanism is activated based on the developed key file, a virtual private line is established with the communication partner device, and the operation of the communication mechanism is terminated. After that, the communication system is configured to delete the key file from the storage unit.
に前記ICカードが離脱されたことを検知したときは、
当該通信機構の動作を停止させるとともに、前記キーフ
ァイルを前記記憶手段から削除するように構成されてい
ることを特徴とする請求項1記載の通信システム。2. The communication device, when detecting that the IC card has been removed during operation of the communication mechanism,
2. The communication system according to claim 1, wherein the operation of the communication mechanism is stopped, and the key file is deleted from the storage unit.
容の可視化を規制する可視化規制手段を有することを特
徴とする請求項1または2記載の通信システム。3. The communication system according to claim 1, wherein the communication device includes a visualization restricting unit that restricts visualization of the contents of the key file.
キーファイルに基づいて利用者認証を行う認証手段と、
前記認証手段による誤認回数が一定回数に達したときは
当該キーファイルをロックするロック手段とを有するこ
とを特徴とする請求項1ないし3のいずれかの項記載の
通信システム。4. An authentication means for performing user authentication based on the stored key file;
4. The communication system according to claim 1, further comprising: a lock unit configured to lock the key file when the number of misrecognitions by the authentication unit reaches a predetermined number.
通信システムにおいて使用される前記ICカードを発行
するシステムであって、 前記ICカードの発行を統括する発行統括者固有の統括
者暗号コード及び前記ICカードの発行を担当する発行
担当者固有の担当者暗号コードを機密保持するカード発
行装置と、前記キーファイルを作成して登録するキー管
理装置とを双方向通信可能に接続して成り、 前記キー管理装置は、 所定権限に基づいて取得した統括者暗号コードを登録す
る手段と、 登録済の統括者暗号コードに基づきチャレンジ・レスポ
ンス方式によって発行担当者登録要求の認証を行い、認
証結果が正当のときに、前記統括者暗号コードで暗号化
された前記担当者暗号コードを前記カード発行装置より
取得する手段と、 取得した担当者暗号コードを登録済の統括者暗号コード
で復号化して登録する手段と、を備え、 登録済の担当者暗号コードに基づく認証後に前記キーフ
ァイルの作成を行うように構成されていることを特徴と
するICカード発行登録システム。5. A system for issuing the IC card used in the communication system according to claim 1, wherein a supervisor encryption unique to an issue supervisor who supervises the issuance of the IC card. A card issuing device that keeps a secret code of a code and a person-in-charge code unique to a person in charge of issuance of the IC card, and a key management device that creates and registers the key file connected so as to be capable of two-way communication. The key management device comprises: means for registering a supervisory code acquired based on a predetermined authority; and authentication of an issuer registration request by a challenge-response method based on the registered supervisory code. Means for acquiring, from the card issuing device, the person-in-charge code encrypted by the supervisor code when the result is valid; Means for decrypting and registering the responsible person's encryption code with the registered supervisor's encrypted code, wherein the key file is created after authentication based on the registered responsible person's encryption code. IC card issue registration system.
通信システムにおいて使用される前記ICカードを発行
するシステムであって、 少なくとも前記ICカードの発行を担当する発行担当者
固有の担当者暗号コードを機密保持するカード発行装置
と、前記キーファイルを作成して登録するキー管理装置
とを双方向通信可能に接続して成り、 前記キー管理装置は、 所定権限に基づいて取得した前記担当者暗号コードを登
録する手段と、 登録済の担当者暗号コードに基づきチャレンジ・レスポ
ンス方式によってキーファイル作成要求の認証を行い、
認証結果が正当のときに渡した所定の機密性セッション
キーを用いて、前記カード発行装置からのファイル基礎
情報の取得、及びこのファイル基礎情報に基づいて作成
した前記キーファイルのカード発行装置への送信を行う
手段と、を備え、 前記カード発行装置は、前記作成されたキーファイルを
対象ICカードに機密的に格納するように構成されてい
ることを特徴とするICカード発行登録システム。6. A system for issuing the IC card used in the communication system according to claim 1, wherein at least a person in charge of issuance of the IC card is assigned. A card issuing device that keeps the encryption code confidential and a key management device that creates and registers the key file are connected so as to enable two-way communication, and the key management device acquires the charge in accordance with a predetermined authority. The key file creation request is authenticated by the challenge-response method based on the means for registering the user encryption code and the registered person encryption code,
Using the predetermined confidentiality session key passed when the authentication result is valid, obtaining the file basic information from the card issuing device, and transmitting the key file created based on the file basic information to the card issuing device. Means for performing transmission, wherein the card issuing device is configured to store the created key file confidentially in a target IC card.
行装置に装着された発行担当者専用のICカードに機密
的に格納されていることを特徴とする請求項5または6
記載のICカード発行登録システム。7. The clerk's code is secretly stored in an IC card dedicated to a clerk in charge attached to the card issuing device.
IC card issuance registration system as described.
発行担当者固有の前記キーファイルが機密的に格納され
ていることを特徴とする請求項7記載のICカード発行
登録システム。8. The IC card issuance / registration system according to claim 7, wherein the key file unique to the issuer is confidentially stored in the IC card dedicated to the issuer.
ICカード発行登録システムにおいて使用される装置で
あって、 少なくとも前記統括者暗号コード及び担当者暗号コード
の作成基礎となる基礎情報を格納した記憶手段と、前記
セッションキーの基礎となる乱数を生成する乱数発生手
段と、前記記憶手段に格納された基礎情報及び前記乱数
発生手段から出力される乱数を所定の権限情報に基づい
て暗号化する暗号化手段と、を有し、前記権限情報の入
力を契機に前記統括者暗号コード、担当者暗号コード、
及びセッションキーのいずれかを生成するように構成さ
れていることを特徴とするキーコード生成装置。9. An apparatus used in the IC card issuance / registration system according to any one of claims 5 to 8, wherein at least basic information which is a basis for creating the supervisory code and the responsible person's code is provided. The stored storage means, a random number generation means for generating a random number serving as a basis of the session key, and a basic information stored in the storage means and a random number output from the random number generation means are encrypted based on predetermined authority information. Encryption means for encrypting, and the input of the authority information triggers the supervisory encryption code, the person in charge encryption code,
And a key code generation device configured to generate one of a session key and a session key.
不正読み出しないし通電の遮断によって前記基礎情報が
消滅するように構成されていることを特徴とする請求項
9記載のキーコード生成装置。10. The storage means is a volatile memory,
10. The key code generation device according to claim 9, wherein the basic information is erased by unauthorized reading or interruption of energization.
間に仮想専用回線を構築する通信機構を利用するための
利用権限情報及び利用者の識別情報を含むキーファイル
が機密的に格納されたICカードを離脱自在に装着する
機構と、記憶手段とを備えたコンピュータ装置に、 前記ICカードが装着されて所定の認証処理が終了した
ときに、当該ICカードに格納されているキーファイル
を前記記憶手段に展開させ、該展開されたキーファイル
に基づき前記通信機構を起動させて前記通信相手装置と
の間に仮想専用回線を構築させ、さらに、前記ICカー
ドの離脱時または前記通信機構の動作終了時に当該キー
ファイルを前記記憶手段から削除させるためのコンピュ
ータプログラムを、前記コンピュータ装置が読み取り可
能な形態で記録して成る記録媒体。11. A key file containing use right information and user identification information for using a communication mechanism for constructing a virtual private line with a communication partner device connected to a public network is confidentially stored. When a predetermined authentication process is completed after the IC card is mounted on a computer device having a mechanism for detachably mounting the IC card and a storage unit, the key file stored in the IC card is deleted. Developed in the storage means, activates the communication mechanism based on the developed key file, establishes a virtual private line with the communication partner device, and furthermore, when the IC card is removed or the communication mechanism is disconnected. A computer program for deleting the key file from the storage means at the end of the operation is recorded in a form readable by the computer device. Recording medium.
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| JP08170897A JP3860280B2 (en) | 1997-03-31 | 1997-03-31 | Communication system, IC card issuance registration system, key code generation device, and recording medium |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| JP08170897A JP3860280B2 (en) | 1997-03-31 | 1997-03-31 | Communication system, IC card issuance registration system, key code generation device, and recording medium |
Publications (2)
| Publication Number | Publication Date |
|---|---|
| JPH10285153A true JPH10285153A (en) | 1998-10-23 |
| JP3860280B2 JP3860280B2 (en) | 2006-12-20 |
Family
ID=13753896
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| JP08170897A Expired - Lifetime JP3860280B2 (en) | 1997-03-31 | 1997-03-31 | Communication system, IC card issuance registration system, key code generation device, and recording medium |
Country Status (1)
| Country | Link |
|---|---|
| JP (1) | JP3860280B2 (en) |
Cited By (14)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2002033610A1 (en) * | 2000-10-17 | 2002-04-25 | Ishii, Mieko | Personal information protective method, personal information protective system, processing device, portable transmitter/receiver, and program |
| JP2002123633A (en) * | 2000-10-17 | 2002-04-26 | Laurel Intelligent Systems Co Ltd | Method and system for protecting personal information, processor and recording medium |
| JP2002183684A (en) * | 2000-12-19 | 2002-06-28 | Koji Toda | Digital network personal authentication system |
| JP2002183685A (en) * | 2000-12-19 | 2002-06-28 | Koji Toda | Ultrasonic individual identification card system |
| JP2003067524A (en) * | 2001-08-28 | 2003-03-07 | Laurel Intelligent Systems Co Ltd | Method, device and program for protecting personal information |
| JP2003196241A (en) * | 2001-12-25 | 2003-07-11 | Dainippon Printing Co Ltd | User authentication information setting device and client computer |
| JP2005310041A (en) * | 2004-04-26 | 2005-11-04 | Systemneeds Inc | Personal authentication infrastructure system |
| JP2007509513A (en) * | 2003-10-13 | 2007-04-12 | トムソン ライセンシング | Method and apparatus for decrypting an encrypted supplemental data set |
| JP2008282414A (en) * | 2008-06-23 | 2008-11-20 | Dainippon Printing Co Ltd | User authentication information setting device and computer program |
| US7668831B2 (en) | 2005-10-27 | 2010-02-23 | International Business Machines Corporation | Assigning unique identification numbers to new user accounts and groups in a computing environment with multiple registries |
| JP2012513644A (en) * | 2008-12-24 | 2012-06-14 | ザ コモンウェルス オブ オーストラリア | Digital video guard |
| JP2017135474A (en) * | 2016-01-25 | 2017-08-03 | 京セラ株式会社 | Electronic device, control device, control program, and operation method of electronic device |
| JP2020067892A (en) * | 2018-10-25 | 2020-04-30 | 三菱重工機械システム株式会社 | Card processing device, toll collection machine, card processing method, and program |
| WO2020085141A1 (en) * | 2018-10-22 | 2020-04-30 | 株式会社ソニー・インタラクティブエンタテインメント | Information processing system, input device, user authentication method, server device, and biometric authentication device |
-
1997
- 1997-03-31 JP JP08170897A patent/JP3860280B2/en not_active Expired - Lifetime
Cited By (19)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US8171556B2 (en) | 2000-10-17 | 2012-05-01 | Mieko Ishii | Personal information protection method, personal information protection system, processing device, portable transmitter/receiver, and program |
| JP2002123633A (en) * | 2000-10-17 | 2002-04-26 | Laurel Intelligent Systems Co Ltd | Method and system for protecting personal information, processor and recording medium |
| WO2002033610A1 (en) * | 2000-10-17 | 2002-04-25 | Ishii, Mieko | Personal information protective method, personal information protective system, processing device, portable transmitter/receiver, and program |
| JP2002183684A (en) * | 2000-12-19 | 2002-06-28 | Koji Toda | Digital network personal authentication system |
| JP2002183685A (en) * | 2000-12-19 | 2002-06-28 | Koji Toda | Ultrasonic individual identification card system |
| JP2003067524A (en) * | 2001-08-28 | 2003-03-07 | Laurel Intelligent Systems Co Ltd | Method, device and program for protecting personal information |
| JP2003196241A (en) * | 2001-12-25 | 2003-07-11 | Dainippon Printing Co Ltd | User authentication information setting device and client computer |
| JP2007509513A (en) * | 2003-10-13 | 2007-04-12 | トムソン ライセンシング | Method and apparatus for decrypting an encrypted supplemental data set |
| JP2005310041A (en) * | 2004-04-26 | 2005-11-04 | Systemneeds Inc | Personal authentication infrastructure system |
| US7668831B2 (en) | 2005-10-27 | 2010-02-23 | International Business Machines Corporation | Assigning unique identification numbers to new user accounts and groups in a computing environment with multiple registries |
| JP2008282414A (en) * | 2008-06-23 | 2008-11-20 | Dainippon Printing Co Ltd | User authentication information setting device and computer program |
| JP2012513644A (en) * | 2008-12-24 | 2012-06-14 | ザ コモンウェルス オブ オーストラリア | Digital video guard |
| JP2017135474A (en) * | 2016-01-25 | 2017-08-03 | 京セラ株式会社 | Electronic device, control device, control program, and operation method of electronic device |
| WO2017130732A1 (en) * | 2016-01-25 | 2017-08-03 | 京セラ株式会社 | Electronic apparatus, control device, and electronic apparatus operating method |
| US10345870B2 (en) | 2016-01-25 | 2019-07-09 | Kyocera Corporation | Electronic apparatus, control device, and operating method of electronic apparatus |
| WO2020085141A1 (en) * | 2018-10-22 | 2020-04-30 | 株式会社ソニー・インタラクティブエンタテインメント | Information processing system, input device, user authentication method, server device, and biometric authentication device |
| JPWO2020085141A1 (en) * | 2018-10-22 | 2021-09-02 | 株式会社ソニー・インタラクティブエンタテインメント | Information processing system and server equipment |
| US12277203B2 (en) | 2018-10-22 | 2025-04-15 | Sony Interactive Entertainment Inc. | Information processing system, input device, user authentication method, server device, and biometric authentication device |
| JP2020067892A (en) * | 2018-10-25 | 2020-04-30 | 三菱重工機械システム株式会社 | Card processing device, toll collection machine, card processing method, and program |
Also Published As
| Publication number | Publication date |
|---|---|
| JP3860280B2 (en) | 2006-12-20 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US6246771B1 (en) | Session key recovery system and method | |
| JP3656688B2 (en) | Cryptographic data recovery method and key registration system | |
| JP3622433B2 (en) | Access credential authentication apparatus and method | |
| CN100454274C (en) | Safty printing using secrete key after being checked | |
| US7885413B2 (en) | Hidden link dynamic key manager for use in computer systems with database structure for storage of encrypted data and method for storage and retrieval of encrypted data | |
| JP3614057B2 (en) | Access qualification authentication method and apparatus, and auxiliary information creation method and apparatus for certification | |
| CN1323538C (en) | A method and system for dynamic identity authentication | |
| US5548721A (en) | Method of conducting secure operations on an uncontrolled network | |
| KR100621420B1 (en) | Network connection system | |
| JPH1127253A (en) | Key recovery system, key recovery device, storage medium storing key recovery program, and key recovery method | |
| US6988198B1 (en) | System and method for initializing operation for an information security operation | |
| JPH07505970A (en) | Encrypted data security methods in secure computer systems | |
| KR20000075650A (en) | Administration and utilization of secret fresh random numbers in a networked environment | |
| JP3860280B2 (en) | Communication system, IC card issuance registration system, key code generation device, and recording medium | |
| CN109981255A (en) | The update method and system of pool of keys | |
| WO2009110457A1 (en) | Authentication information generation system, authentication information generation method, and authentication information generation program utilizing a client device and said method | |
| JPH07325785A (en) | Network user authentication method, encrypted communication method, application client and server | |
| JPH08320847A (en) | Password management system | |
| CN110098925A (en) | Based on unsymmetrical key pond to and random number quantum communications service station cryptographic key negotiation method and system | |
| KR100286904B1 (en) | System and method for security management on distributed PC | |
| CN108667801A (en) | A kind of Internet of Things access identity safety certifying method and system | |
| JP4657706B2 (en) | Authority management system, authentication server, authority management method, and authority management program | |
| KR20080087917A (en) | One-time password generation method, key issuance system and one-time password authentication system | |
| JP2004070875A (en) | Secure system | |
| JP3481755B2 (en) | Data backup / restore method and system |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| A131 | Notification of reasons for refusal |
Free format text: JAPANESE INTERMEDIATE CODE: A131 Effective date: 20060104 |
|
| A521 | Written amendment |
Free format text: JAPANESE INTERMEDIATE CODE: A523 Effective date: 20060224 |
|
| A131 | Notification of reasons for refusal |
Free format text: JAPANESE INTERMEDIATE CODE: A131 Effective date: 20060404 |
|
| A521 | Written amendment |
Free format text: JAPANESE INTERMEDIATE CODE: A523 Effective date: 20060516 |
|
| A02 | Decision of refusal |
Free format text: JAPANESE INTERMEDIATE CODE: A02 Effective date: 20060704 |
|
| A521 | Written amendment |
Free format text: JAPANESE INTERMEDIATE CODE: A523 Effective date: 20060720 |
|
| A911 | Transfer to examiner for re-examination before appeal (zenchi) |
Free format text: JAPANESE INTERMEDIATE CODE: A911 Effective date: 20060825 |
|
| TRDD | Decision of grant or rejection written | ||
| A01 | Written decision to grant a patent or to grant a registration (utility model) |
Free format text: JAPANESE INTERMEDIATE CODE: A01 Effective date: 20060919 |
|
| A61 | First payment of annual fees (during grant procedure) |
Free format text: JAPANESE INTERMEDIATE CODE: A61 Effective date: 20060921 |
|
| R150 | Certificate of patent or registration of utility model |
Free format text: JAPANESE INTERMEDIATE CODE: R150 |
|
| FPAY | Renewal fee payment (event date is renewal date of database) |
Free format text: PAYMENT UNTIL: 20120929 Year of fee payment: 6 |
|
| FPAY | Renewal fee payment (event date is renewal date of database) |
Free format text: PAYMENT UNTIL: 20120929 Year of fee payment: 6 |
|
| S303 | Written request for registration of pledge or change of pledge |
Free format text: JAPANESE INTERMEDIATE CODE: R316304 |
|
| FPAY | Renewal fee payment (event date is renewal date of database) |
Free format text: PAYMENT UNTIL: 20120929 Year of fee payment: 6 |
|
| R360 | Written notification for declining of transfer of rights |
Free format text: JAPANESE INTERMEDIATE CODE: R360 |
|
| FPAY | Renewal fee payment (event date is renewal date of database) |
Free format text: PAYMENT UNTIL: 20120929 Year of fee payment: 6 |
|
| R370 | Written measure of declining of transfer procedure |
Free format text: JAPANESE INTERMEDIATE CODE: R370 |
|
| FPAY | Renewal fee payment (event date is renewal date of database) |
Free format text: PAYMENT UNTIL: 20120929 Year of fee payment: 6 |
|
| S303 | Written request for registration of pledge or change of pledge |
Free format text: JAPANESE INTERMEDIATE CODE: R316304 |
|
| FPAY | Renewal fee payment (event date is renewal date of database) |
Free format text: PAYMENT UNTIL: 20120929 Year of fee payment: 6 |
|
| R360 | Written notification for declining of transfer of rights |
Free format text: JAPANESE INTERMEDIATE CODE: R360 |
|
| FPAY | Renewal fee payment (event date is renewal date of database) |
Free format text: PAYMENT UNTIL: 20120929 Year of fee payment: 6 |
|
| R350 | Written notification of registration of transfer |
Free format text: JAPANESE INTERMEDIATE CODE: R350 |
|
| FPAY | Renewal fee payment (event date is renewal date of database) |
Free format text: PAYMENT UNTIL: 20120929 Year of fee payment: 6 |
|
| S303 | Written request for registration of pledge or change of pledge |
Free format text: JAPANESE INTERMEDIATE CODE: R316303 |
|
| R371 | Transfer withdrawn |
Free format text: JAPANESE INTERMEDIATE CODE: R371 |
|
| FPAY | Renewal fee payment (event date is renewal date of database) |
Free format text: PAYMENT UNTIL: 20120929 Year of fee payment: 6 |
|
| S303 | Written request for registration of pledge or change of pledge |
Free format text: JAPANESE INTERMEDIATE CODE: R316303 |
|
| R350 | Written notification of registration of transfer |
Free format text: JAPANESE INTERMEDIATE CODE: R350 |
|
| FPAY | Renewal fee payment (event date is renewal date of database) |
Free format text: PAYMENT UNTIL: 20120929 Year of fee payment: 6 |
|
| FPAY | Renewal fee payment (event date is renewal date of database) |
Free format text: PAYMENT UNTIL: 20130929 Year of fee payment: 7 |
|
| FPAY | Renewal fee payment (event date is renewal date of database) |
Free format text: PAYMENT UNTIL: 20130929 Year of fee payment: 7 |
|
| FPAY | Renewal fee payment (event date is renewal date of database) |
Free format text: PAYMENT UNTIL: 20130929 Year of fee payment: 7 |
|
| R250 | Receipt of annual fees |
Free format text: JAPANESE INTERMEDIATE CODE: R250 |
|
| R250 | Receipt of annual fees |
Free format text: JAPANESE INTERMEDIATE CODE: R250 |
|
| R250 | Receipt of annual fees |
Free format text: JAPANESE INTERMEDIATE CODE: R250 |
|
| R250 | Receipt of annual fees |
Free format text: JAPANESE INTERMEDIATE CODE: R250 |
|
| EXPY | Cancellation because of completion of term |